Who operates Intent
Intent is a focus and goal-planning app for Windows. It is operated by Arnav Sharma, an individual (“we”, “us”). This policy explains what information Intent handles when you use the Windows app and this website, and what we do with it.
Questions or requests about your information: arnavsharma8079@gmail.com.
What stays on your device
Intent is local-first. Your productivity content is stored in a database on your own computer and is not sent to our servers. That includes:
- monthly goals, daily goals and tasks, and your current task;
- focus sessions, interruptions and how you returned after them;
- reflections, weekly and monthly reviews, and progress statistics, which are calculated on your device;
- your settings and your companion (Kero) preferences.
Intent does not record keystrokes, take screenshots, read your files, or log which windows or apps you use. To hide the companion while a fullscreen app or presentation is in front, the app checks on your device whether the window in front covers the screen. That check does not read window titles or app names, and its result is not stored or sent anywhere.
Because this content never reaches us, we cannot see it, recover it or delete it for you. It stays under your control, and uninstalling Intent or deleting its local data removes it from that device.
What we collect
Our servers receive only what is needed to create your account and keep you signed in.
Account information from Google
- your Google account identifier (a stable ID Google assigns to your account);
- your email address and whether Google has verified it;
- your name as shown on your Google profile.
Device information sent when you sign in
- a random installation identifier created by the app;
- your computer’s name (the Windows computer name);
- your Windows version and the Intent app version.
Account and session records
- an internal account ID, when your account was created, your last sign-in and when you last used the service;
- the devices signed in to your account and when they were signed out;
- sign-in session records. The tokens themselves are stored only as one-way hashes.
Technical request data
When the app talks to our API, our servers log basic request details: your IP address, the time, the request method and path, the response status and how long it took. Query strings, request and response bodies, and request headers are not written to these logs. Your IP address is also used briefly, in memory, to rate-limit sign-in requests.
Google sign-in
Intent uses Google sign-in to create and identify your account. When you choose “Sign in with Google”, the app opens Google in your browser. You sign in with Google directly, and we never see or store your Google password.
Intent requests only the basic sign-in permissions: openid, email and profile. From these we use your Google account identifier, email address, verification status and name, as listed above, only to sign you in and to recognise your account on each of your devices. Intent does not request access to your Gmail, Google Drive, Calendar, contacts or any other Google data. Intent does not request Google refresh tokens, and the Google sign-in tokens returned during authentication are used for the sign-in flow and are not stored by Intent. We do not use information from Google for advertising, and we do not sell it.
You can remove Intent’s access at any time from your Google Account’s third-party access settings. Google’s own handling of your information is described in the Google Privacy Policy.
Product analytics
Intent does not currently send product analytics or usage telemetry. If we introduce product analytics in the future, we will limit collection to an allowlisted set of usage events, obtain consent where required, and update this Privacy Policy before collection begins.
How we use information
- to sign you in, keep you signed in, and recognise your account across your devices;
- to let a device sign out, and to end sessions that are no longer valid;
- to protect the service: rate-limiting, detecting misuse, and investigating errors;
- to operate, maintain and improve the reliability of the service.
We do not sell your personal information, use it for advertising, or share it with data brokers. We may disclose information if we are required to by law.
Where information is stored
The account information above is stored in a database on our server in Google Cloud’s Mumbai, India region (asia-south1). Backups of that database are stored privately in Google Cloud Storage in the same region. If you use Intent from outside India, your account information is transferred to and processed in India.
On your computer, Intent keeps your productivity content in its local database and stores your sign-in session in Windows Credential Manager.
Security
- All traffic between the app and our API uses HTTPS.
- The database is not reachable from the internet. Only the API on the same server can connect to it.
- Administrative access to the server is restricted and does not allow direct SSH connections from the internet.
- Sign-in uses Google’s OAuth flow with additional one-time checks. Session tokens are stored on our servers only as hashes.
- Server secrets are kept on the server and are never included in the app.
No system is perfectly secure, and we cannot guarantee absolute security. Your local data is protected by the security of your own Windows account and device.
Services we rely on
- Google: Google sign-in for authentication, and Google Cloud for hosting our server and storing backups.
- Let’s Encrypt: issues the HTTPS certificate for our API. It does not receive your account information.
- Hostinger: our domain and DNS provider, which resolves the
intentapp.appaddresses your app and browser look up.
We do not use advertising networks or third-party analytics services.
How long we keep information
- Account information is kept while your account exists. You can ask us to delete it (see below).
- Sign-in sessions expire after 60 days without use. Expired session records may remain in the database until they are cleaned up.
- Web server access logs, which include IP addresses, are kept for 30 days.
- API service logs are kept on the server for a limited time and are rotated as they reach their size limit.
- Database backups are kept for up to about four months. Information deleted from the database can remain in older backups until those backups expire.
Your choices and requests
- Sign out in the app to end that device’s session.
- Remove Intent’s access to your Google account in your Google Account settings.
- Delete local data by uninstalling Intent or removing its data from your device.
- Access, correction or deletion: email arnavsharma8079@gmail.com from the email address on your account. Intent does not yet have an in-app account deletion feature, so deletion requests are handled by email.
Depending on where you live, you may have additional rights under applicable law. Contact us and we will respond to your request.
Children
Intent is intended for users aged 13 and older. Intent is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we will delete it. Additional age or consent requirements may apply where required by applicable law.
Changes to this policy
We will update this policy if what Intent collects or how we use it changes, and we will revise the effective date above. If a change is significant, we will take reasonable steps to let you know, for example on this website or in the app, before it takes effect.
Contact
Intent is operated by Arnav Sharma. For privacy questions or requests, email arnavsharma8079@gmail.com.